
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-42569 is an improper authorization verification vulnerability affecting AR Emoji in Samsung mobile devices prior to SMR Dec-2023 Release 1. The vulnerability was discovered and reported on August 10, 2023 by researcher OrangeCat, and affects Android versions 11, 12, and 13 (Samsung Security).
The vulnerability has been assigned a CVSS v3.1 base score of 3.3 LOW by NIST with vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N, while Samsung Mobile assessed it as 4.0 MEDIUM with vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. The vulnerability is classified under CWE-863 (Incorrect Authorization) (NVD).
The vulnerability allows attackers to read sandbox data of AR Emoji, potentially exposing user data stored within the AR Emoji application's sandbox environment (Samsung Security).
Samsung has addressed this vulnerability by adding proper authorization verification logic to prevent unauthorized access. The fix is included in the SMR Dec-2023 Release 1 security update (Samsung Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."